Method, system and equipment for realizing secure communication of MySQL database and medium

By using encrypted SSL private keys and self-signed certificates in MySQL databases, enabling the SSL/TLS protocol, and implementing automated certificate updates, the problems of data leakage, tampering and man-in-the-middle attacks during MySQL database communication are solved, and communication security and reliability are significantly improved.

CN120165856APending Publication Date: 2025-06-17INSPUR YUNZHOU (SHANDONG) IND INTERNET CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510359157.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-25
Publication Date
2025-06-17

AI Technical Summary

Technical Problem

MySQL databases face the risks of data leakage, tampering and man-in-the-middle attacks during communication. Traditional communication methods have shortcomings in identity verification and self-signed certificate management.

Method used

By generating an SSL private key and a self-signed certificate, encrypting the SSL private key and storing it on the server, enabling the SSL/TLS protocol, encrypting communication between the client and the server, and achieving automated certificate updates and management.

Benefits of technology

It effectively prevents data leakage and tampering during transmission, reduces the risk of man-in-the-middle attacks, ensures authentication between the client and the server, and improves the security and reliability of MySQL database communication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120165856A_ABST
    Figure CN120165856A_ABST
Patent Text Reader

Abstract

The invention provides a method, a system, equipment and a medium for realizing secure communication of a MySQL database, and belongs to the technical field of data encryption, and the method comprises the following steps: generating an SSL private key for a server in advance, generating a self-signature certificate by using the SSL private key, encrypting the SSL private key, and storing the encrypted SSL private key in the server; starting an SSL / TLS protocol when the server configures the MySQL database, and importing a self-signature certificate and an encrypted SSL private key; and the server responds to a request of connecting the MySQL database from the client, decrypts the SSL private key, and performs encrypted communication using the SSL / TLS protocol with the client through the SSL private key and the self-signature certificate. According to the method, leakage and tampering of the data in the MySQL database in the transmission process are prevented through the SSL private key, and the risk of suffering from man-in-the-middle attack is reduced; and the automatic updating of the self-visa ensures that the SQL database system can be continuously kept in a safe state.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the technical field of data encryption, and relates to a method, system, device and medium for realizing secure communication of MySQL databases. Background Art

[0002] With the development of Internet technology, the security of data has become increasingly important. Especially in database management systems, ensuring data transmission and storage security has become a key issue. As an open-source relational data management system widely used, MySQL undertakes the tasks of storing and managing a large amount of key data in various application scenarios, covering sensitive content such as financial transaction information, user personal privacy data, and even commercial secrets. However, with the evolution of network attack technologies and the increasing complexity of malicious attack means, MySQL databases face security problems during communication, and the existing communication methods have obvious deficiencies in many aspects.

[0003] First of all, in the traditional MySQL communication mode, data is usually transmitted in plain text over the network. This enables attackers to easily intercept data packets on the data transmission path using network sniffing tools, thereby obtaining sensitive information in the database. Secondly, there are vulnerabilities in the existing MySQL communication methods in terms of authentication. When the client establishes a connection with the server, there is a lack of effective authentication means and it is easily subject to man-in-the-middle attacks. Attackers can disguise themselves as legitimate clients or servers, insert themselves into the communication link, intercept and tamper with data, and ultimately cause the client or server to be unable to determine whether the received data has been tampered with during transmission, which may lead to the use of incorrect data for business processing, resulting in business logic errors and data inconsistency problems. Finally, although MySQL supports the use of self-signed certificates to establish secure connections, in actual applications, there are many problems in the management of self-signed certificates and private keys. The private key of a self-signed certificate is the core part of certificate verification and encrypted communication. If the private key is not properly protected, attackers may obtain the content of data communication by means of brute force cracking, stealing the private key file, etc., thereby endangering data security. In addition, the existing management methods of self-signed certificates and private keys lack automation and standardization. Operations such as certificate update and key replacement often require manual intervention, which is prone to omissions, resulting in the inability to continuously guarantee the security of the system. Summary of the Invention

[0004] In a first aspect, an embodiment of this application provides a method for realizing secure communication of a MySQL database, including the following steps: S1. Generate an SSL private key for the server in advance, generate a self-signed certificate using the SSL private key, and store the encrypted SSL private key on the server; S2. Enable the SSL / TLS protocol when configuring the MySQL database on the server, and import the self-signed certificate and the encrypted SSL private key; S3. The server responds to the client's request to connect to the MySQL database, decrypts the SSL private key, and conducts encrypted communication with the client using the SSL / TLS protocol with the SSL private key and the self-signed certificate.

[0005] Further, the specific steps of step S1 are as follows: S11. Use the OpenSSL tool on the server to generate an SSL private key and an SSL public key of a preset length through the RSA algorithm; S12. Sign the content containing the server identity information with the SSL private key to create a certificate signing request; S13. Generate a certificate based on the certificate signing request, combined with the SSL public key, the server identity information, and a preset certificate expiration period, and sign the certificate with the SSL private key to obtain a self-signed certificate; S14. Encrypt the SSL private key to obtain the SSL private key ciphertext, and store the self-signed certificate and the SSL private key ciphertext on the server.

[0006] Further, the specific steps of step S2 are as follows: S21. When configuring the MySQL database on the server, obtain the MySQL configuration file, the storage location of the self-signed certificate, and the storage location of the SSL private key ciphertext; S22. Add the storage location of the self-signed certificate and the storage location of the SSL private key ciphertext to the MySQL configuration file; S23. Restart the MySQL database, and the SSL / TLS protocol takes effect.

[0007] Further, the specific steps of step S3 are as follows: S31. When the client needs to connect to the MySQL database, create a request to connect using the SSL / TLS protocol; S32. The server responds to the client's request to connect to the MySQL database and sends the self-signed certificate to the client; S33. The server decrypts the SSL private key ciphertext to obtain the SSL private key; S34. The client verifies the validity of the self-signed certificate, generates a session key after the verification passes, then obtains the SSL public key from the self-signed certificate, encrypts the session key with the SSL public key to obtain the session key ciphertext, and sends the session key ciphertext to the server; S35. The server decrypts the session key ciphertext with the SSL private key to obtain the session key; S36. The client and the server use the session key for encrypted communication of the SSL / TLS protocol.

[0008] Furthermore, the following steps are further included in step S3: SS1. The server generates a timed certificate update task according to the certificate expiration date; SS2. After the certificate update task is started, the server regenerates the SSL private key and the self-signed certificate, then encrypts the regenerated SSL private key, stores the encrypted SSL private key ciphertext and the self-signed certificate, and then updates the storage locations of the self-signed certificate and the SSL private key ciphertext in the MySQL configuration file.

[0009] Furthermore, the specific steps of step S14 are as follows: S141. The server generates an AES key, and uses the AES key to encrypt the SSL private key to obtain the SSL private key ciphertext; S142. Store the signature certificate on the server and record the storage location; S143. The server creates an encrypted folder, stores the SSL private key ciphertext in the encrypted folder, and records the storage location; The specific steps of step S33 are as follows: S331. The server applies for administrator authorization to obtain access rights to the encrypted folder; S332. The server obtains the SSL private key ciphertext from the encrypted folder and decrypts it using the AES key to obtain the SSL private key.

[0010] Furthermore, the specific steps of step S14 are as follows: S141. Pre-generate the server key pair to obtain the server public key and the server private key, and securely store the server private key; S142. Use the server public key to encrypt the SSL private key to obtain the SSL private key ciphertext; S142. Store the signature certificate on the server and record the storage location; S143. The server creates an encrypted folder, stores the SSL private key ciphertext in the encrypted folder, and records the storage location; The specific steps of step S33 are as follows: S331. The server applies for administrator authorization to obtain access rights to the encrypted folder and obtains the server private key at the same time; S332. The server obtains the SSL private key ciphertext from the encrypted folder and decrypts it using the server private key to obtain the SSL private key.

[0011] In a second aspect, an embodiment of the present application further provides a system for implementing secure communication of a MySQL database, including: The SSL private key encryption and self-signed certificate generation module is used to pre-generate an SSL private key for the server, generate a self-signed certificate using the SSL private key, and store the encrypted SSL private key on the server; The secure communication configuration module is used to enable the SSL / TLS protocol when configuring the MySQL database on the server, and import the self-signed certificate and the encrypted SSL private key; The secure communication module is used to decrypt the SSL private key when the server responds to the client's request to connect to the MySQL database, and perform encrypted communication with the client using the SSL / TLS protocol through the SSL private key and the self-signed certificate.

[0012] Thirdly, an embodiment of the present application further provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, the steps of the method for realizing secure communication of the MySQL database as described in the first aspect are implemented.

[0013] Fourthly, an embodiment of the present application further provides a storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the method for realizing secure communication of the MySQL database as described in the first aspect are implemented.

[0014] It can be seen from the above technical solutions that the present application has the following advantages: In the method, system, device, and medium for realizing secure communication of the MySQL database provided by the present application, through the encrypted storage of the SSL private key, the effective management of the self-signed certificate, and the process of realizing SSL / TLS communication, the leakage and tampering of data during the transmission process are prevented, and the risk of being attacked by a man-in-the-middle is reduced; at the same time, the automated certificate update mechanism ensures that the SQL database system can continuously maintain a secure state, reduces the security risks brought by manual intervention, and comprehensively improves the security and reliability of MySQL database communication. Description of the Drawings

[0015] In order to more clearly illustrate the technical solutions of the present application, the drawings required for description will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0016] Figure 1 It is a schematic flowchart of the method for realizing secure communication of the MySQL database of the present invention.

[0017] Figure 2 It is a schematic diagram of the system for realizing secure communication of the MySQL database of the present invention. Detailed implementation manners

[0018] In the following specific steps of the method for implementing secure communication of the MySQL database, various embodiments of the present disclosure will be described more comprehensively. The present disclosure may have various embodiments, and adjustments and changes can be made therein. However, it should be understood that there is no intention to limit the various embodiments of the present disclosure to the specific embodiments disclosed herein, but the present disclosure should be understood to cover all adjustments, equivalents, and / or alternative solutions that fall within the spirit and scope of the various embodiments of the present disclosure.

[0019] Exemplarily, with the continuous progress of Internet technology, data security issues are becoming more and more serious in database management. Especially for MySQL, a widely used open-source relational database management system, it is responsible for storing and managing a large amount of sensitive data including financial transactions, user privacy, and business secrets. However, the MySQL database is facing severe challenges in communication security, and there are multiple hidden dangers in its traditional communication methods.

[0020] First of all, the traditional communication mode of MySQL often transmits data in plain text, which makes the data have no security guarantee during the transmission process. Attackers can easily intercept the data packets using network sniffing tools and steal sensitive information in the database. Secondly, there are vulnerabilities in the authentication mechanism when MySQL establishes a connection between the client and the server, lacking sufficient security guarantee. This provides an opportunity for man-in-the-middle attacks. Attackers can disguise themselves as legitimate users or servers, insert themselves into the communication link, intercept and tamper with the data. In this way, it is difficult for the client or the server to determine whether the received data is true and reliable, which may lead to problems such as incorrect business processing and data inconsistency. Moreover, although MySQL supports the use of self-signed certificates to establish a secure connection, the management of self-signed certificates and private keys has many problems. As the private key is the key to certificate verification and encrypted communication, once it is not properly protected, it may be obtained by attackers through brute force cracking, stealing files, etc., thus endangering data security. In addition, the management methods of self-signed certificates and private keys lack automation and standardization. Operations such as certificate update and key replacement rely on manual work, which is prone to omissions, resulting in the system security being difficult to continuously guarantee.

[0021] In view of the above problems, this embodiment provides a method for implementing secure communication of the MySQL database. By introducing the SSL / TLS protocol and combining self-signed certificates and encrypted storage of SSL private keys, the security of the MySQL database during the communication process is effectively improved; it not only prevents the data from being intercepted and tampered with during the transmission process, but also ensures the authentication between the client and the server, enhancing the security protection ability of the database system. At the same time, through the automated certificate update and management mechanism, the burden of manual management is reduced, and the maintainability of the system is improved.

[0022] The technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0023] Please refer to Figure 1 The figure shows a flowchart of a method for realizing secure communication of a MySQL database in a specific embodiment. The method includes the following steps: S1. Generate an SSL private key for the server in advance, generate a self-signed certificate using the SSL private key, and store the encrypted SSL private key on the server; It should be noted that generating the SSL private key provides a basic key for subsequent encrypted communication. The SSL private key is the key to data encryption and decryption in the process of secure communication, ensuring the confidentiality of data during transmission; generating a self-signed certificate can be used for authentication. The client verifies the certificate to confirm the identity of the server and prevent man-in-the-middle attacks; at the same time, the public key contained in the self-signed certificate can be used to encrypt the session key, enhancing the security of communication; storing the encrypted SSL private key on the server prevents the SSL private key from being illegally obtained during storage; even if the server is attacked, the attacker cannot directly obtain the SSL private key, thus protecting the security of the entire communication system; S2. Enable the SSL / TLS protocol when configuring the MySQL database on the server, and import the self-signed certificate and the encrypted SSL private key; It should be noted that enabling the SSL / TLS protocol can provide encryption and authentication functions for data transmission, and enabling this protocol in the MySQL database ensures the security of data transmission between the client and the server, preventing data from being stolen or tampered with; importing the self-signed certificate and the encrypted SSL private key enables the MySQL database to correctly use the certificate and private key for authentication and encrypted communication, providing a basis for subsequent secure communication; S3. The server responds to the client's request to connect to the MySQL database, decrypts the SSL private key, and performs encrypted communication using the SSL / TLS protocol with the client through the SSL private key and the self-signed certificate; It should be noted that when the client initiates a connection request, the server needs to use the private key to decrypt the encrypted session key sent by the client. Therefore, decrypting the SSL private key is the key to achieving encrypted communication. Perform encrypted communication using the SSL / TLS protocol: Through the SSL private key and the self-signed certificate, the client and the server can use the SSL / TLS protocol for encrypted communication, ensuring the security of data during transmission and effectively protecting the data security in the MySQL database.

[0024] In this embodiment, encrypted communication is carried out through the SSL / TLS protocol to ensure that data is not intercepted and tampered with during transmission; use the self-signed certificate for authentication to prevent man-in-the-middle attacks and ensure the true identities of both communication parties; and by encrypting and storing the SSL private key, the key management process is simplified.

[0025] Furthermore, as a refinement and extension of the specific implementation manner of the above embodiment, in order to fully illustrate the specific implementation process in this embodiment, another method for realizing secure communication of the MySQL database is provided. This method includes the following steps: S1. Generate an SSL private key for the server in advance, generate a self-signed certificate using the SSL private key, and store the encrypted SSL private key on the server. The specific steps of step S1 are as follows: S11. Use the OpenSSL tool on the server to generate an SSL private key and an SSL public key of a preset length through the RSA algorithm; Exemplarily, generate a 2048-bit SSL private key through the command line and store it in the private.key file: openssl genrsa -out private.key 2048 S12. Sign the content containing the server identity information using the SSL private key to create a certificate signing request; Exemplarily, create a certificate signing request through the following instruction: openssl req -new -key private.key -out csr.csr S13. Generate a certificate based on the certificate signing request, in combination with the SSL public key, the server identity information, and a preset certificate expiration period, and sign the certificate using the SSL private key to obtain a self-signed certificate; Exemplarily, create a self-signed certificate with a validity period of 365 days through the following instruction: openssl x509 -req -days 365 -in csr.csr -signkey private.key -out certificate.crt S14. Encrypt the SSL private key to obtain the SSL private key ciphertext, and store the self-signed certificate and the SSL private key ciphertext on the server; It should be noted that using the OpenSSL tool and the RSA algorithm to generate the SSL private key and public key ensures the security and generation standardization of the key; creating a certificate signing request and generating a self-signed certificate through the private key signature makes the certificate authentic and enhances the reliability of identity authentication; encrypting and storing the SSL private key further improves the security of the private key and prevents security risks caused by the leakage of the SSL private key; S2. Enable the SSL / TLS protocol when configuring the MySQL database on the server, and import the self-signed certificate and the encrypted SSL private key; The specific steps of step S2 are as follows: S21. When configuring the MySQL database on the server, obtain the MySQL configuration file, the storage location of the self-signed certificate, and the storage location of the SSL private key ciphertext; Exemplarily, when configuring the MySQL database on the server, open the MySQL configuration file my.cnf and add or modify the following configuration items to enable the SSL / TLS protocol: ssl-ca= / path / to / certificate.crt # Self-signed certificate path ssl-cert= / path / to / certificate.crt # Self-signed certificate path ssl-key= / path / to / encrypted_private.key # Encrypted private key path S22. Add the storage location of the self-signed certificate and the storage location of the SSL private key ciphertext to the MySQL configuration file; S23. Restart the MySQL database, and the SSL / TLS protocol takes effect; It should be noted that through the operations of obtaining the relevant storage locations, adding them to the configuration file, and restarting the database to make the protocol take effect when enabling the SSL / TLS protocol in the server configuration of the MySQL database, it is ensured that the MySQL database can correctly use the self-signed certificate and the encrypted private key for secure communication, providing guarantee for subsequent client connections and data transmissions; S3. The server responds to the client's request to connect to the MySQL database, decrypts the SSL private key, and conducts encrypted communication with the client using the SSL / TLS protocol through the SSL private key and the self-signed certificate; The specific steps of step S3 are as follows: S31. When the client needs to connect to the MySQL database, create a request to connect using the SSL / TLS protocol; S32. The server responds to the client's request to connect to the MySQL database and sends the self-signed certificate to the client; S33. The server decrypts the SSL private key ciphertext to obtain the SSL private key; S34. The client verifies the validity of the self-signed certificate, generates a session key after successful verification, obtains the SSL public key from the self-signed certificate, encrypts the session key using the SSL public key to obtain the session key ciphertext, and sends the session key ciphertext to the server; S35. The server decrypts the session key ciphertext using the SSL private key to obtain the session key; S36. The client and the server perform encrypted communication using the SSL / TLS protocol with the session key; It should be noted that through the specific process of the client initiating a connection request, the server sending a certificate, decrypting the private key, the client verifying the certificate, generating and encrypting the session key for transmission, the server decrypting the session key, and finally performing encrypted communication using the session key, the security and integrity of the data during transmission are ensured, effectively preventing the data from being stolen or tampered with.

[0026] In an embodiment of the present invention, based on step S14 and step S33, a possible embodiment will be given below to non-restrictively elaborate on its specific implementation.

[0027] The specific steps of step S14 are as follows: S141. The server generates an AES key, encrypts the SSL private key using the AES key to obtain the SSL private key ciphertext; S142. Store the signed certificate on the server and record the storage location; S143. The server creates an encrypted folder, stores the SSL private key ciphertext in the encrypted folder, and records the storage location; The specific steps of step S33 are as follows: S331. The server applies for administrator authorization to obtain access rights to the encrypted folder; S332. The server obtains the SSL private key ciphertext from the encrypted folder and decrypts it using the AES key to obtain the SSL private key.

[0028] It should be noted that the generated private key is encrypted using the symmetric encryption algorithm AES and the encrypted private key is stored in a secure location. For example, the encrypted folder can be set to be accessible only by authorized administrators, thereby ensuring the security of the private key.

[0029] In another embodiment of the present invention, based on step S14 and step S33, a possible embodiment will be given below to non-restrictively elaborate on its specific implementation.

[0030] The specific steps of step S14 are as follows: S141. Pre-generate a server key pair to obtain a server public key and a server private key, and securely store the server private key; S142. Encrypt the SSL private key using the server public key to obtain an SSL private key ciphertext; S142. Store the signature certificate on the server and record the storage location; S143. The server creates an encrypted folder, stores the SSL private key ciphertext in the encrypted folder, and records the storage location; The specific steps of step S33 are as follows: S331. The server applies for administrator authorization to obtain access rights to the encrypted folder, and at the same time obtains the server private key; S332. The server obtains the SSL private key ciphertext from the encrypted folder and decrypts it using the server private key to obtain the SSL private key.

[0031] It should be noted that, using an asymmetric encryption algorithm, such as RSA or ECC, the SSL private key is encrypted using the server's public key to ensure that even if the SSL private key is intercepted, it cannot be cracked.

[0032] It should be understood that the magnitudes of the sequence numbers of the steps in the above embodiments do not mean the order of execution. The order of execution of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present invention.

[0033] As Figure 2 shown, the following is an embodiment of a system for implementing secure communication of a MySQL database provided by an embodiment of the present disclosure. This system and the method for implementing secure communication of a MySQL database in the above embodiments belong to the same inventive concept. For the details not described in detail in the embodiment of the system for implementing secure communication of a MySQL database, reference can be made to the embodiments of the method for implementing secure communication of a MySQL database.

[0034] The system includes: An SSL private key encryption and self-signed certificate generation module, configured to pre-generate an SSL private key for the server, generate a self-signed certificate using the SSL private key, and store the encrypted SSL private key on the server; A secure communication configuration module, configured to enable the SSL / TLS protocol when configuring the MySQL database on the server, and import the self-signed certificate and the encrypted SSL private key; A secure communication module, configured to decrypt the SSL private key when the server responds to a request from a client to connect to the MySQL database, and perform encrypted communication with the client using the SSL / TLS protocol through the SSL private key and the self-signed certificate.

[0035] Through the mutual cooperation of the SSL private key encryption and self-signed certificate generation module, the secure communication configuration module, and the secure communication module in this embodiment, the secure communication function of the MySQL database is realized.

[0036] The method for realizing secure communication of the MySQL database provided by the embodiments of this application can be applied to electronic devices. Those skilled in the art can understand that the structure of the electronic devices involved in the embodiments of the present invention does not constitute a limitation on the electronic devices. The electronic devices may include more or fewer components than shown in the figures, or combine certain components, or have different component arrangements. In the embodiments of the present invention, the electronic devices include, but are not limited to, laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic devices may also represent various forms of mobile devices, such as personal digital assistants, cellular phones, smart phones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the embodiments of this application described herein and / or claimed.

[0037] The electronic device may include a processor, an external memory interface, an internal memory, a universal serial bus (USB) interface, a charging management module, a power management module, a battery, a wireless communication module, an audio module, a speaker, a microphone, a sensor module, keys, a camera, a display screen, and a SIM card interface, etc.

[0038] It can be understood that the structure schematically shown in the embodiments of this application does not constitute a specific limitation on the electronic device. In other embodiments of this application, the electronic device may include more or fewer components than shown in the figures, or combine certain components, or split certain components, or have different component arrangements. The components shown in the figures may be implemented in hardware, software, or a combination of software and hardware.

[0039] The processor may include one or more processing units. For example, the processor may include a central processing unit (CPU), an application processor (AP), a modem processor, a graphics processing unit (GPU), an image signal processor (ISP), a controller, a memory, a video codec, a digital signal processor (DSP), a baseband processor, and / or a neural network processing unit (NPU), etc. Among them, different processing units may be independent devices or integrated in one or more processors.

[0040] Among them, the processor may be the nerve center and command center of the electronic device. The controller can generate operation control signals according to the instruction operation code and timing signals to complete the control of fetching and executing instructions.

[0041] A memory may also be provided in the processor for storing instructions and data. In some embodiments, the memory in the processor is a cache memory. This memory can store the instructions or data that the processor has just used or recycled. If the processor needs to use the instruction or data again, it can directly call it from this memory. This avoids repeated accesses, reduces the waiting time of the processor, and thus improves the system efficiency.

[0042] The above electronic device implements the technical solution of the method for realizing secure communication of the MySQL database in the present application, which pre-generates an SSL private key for the server, generates a self-signed certificate using the SSL private key, and stores the encrypted SSL private key in the server; enables the SSL / TLS protocol when configuring the MySQL database in the server, and imports the self-signed certificate and the encrypted SSL private key; the server decrypts the SSL private key in response to the client's request to connect to the MySQL database, and performs encrypted communication with the client using the SSL / TLS protocol through the SSL private key and the self-signed certificate, achieving the beneficial effects of effectively improving the security of the MySQL database during the communication process; not only preventing the data from being intercepted and tampered with during the transmission process, but also ensuring the authentication between the client and the server, enhancing the security protection ability of the database system. At the same time, through the automated certificate update and management mechanism, the burden of manual management is reduced, and the maintainability of the SQL database system is improved.

[0043] In the storage medium provided by the present application, there is a program product for realizing the method of secure communication of the MySQL database.

[0044] The methods for implementing secure communication of a MySQL database include: generating an SSL private key for the server in advance, generating a self-signed certificate using the SSL private key, and storing the encrypted SSL private key on the server; enabling the SSL / TLS protocol when configuring the MySQL database on the server, and importing the self-signed certificate and the encrypted SSL private key; when the server responds to the client's request to connect to the MySQL database, decrypting the SSL private key, and performing encrypted communication using the SSL / TLS protocol with the client through the SSL private key and the self-signed certificate.

[0045] In some possible implementation manners, the method for implementing secure communication of a MySQL database according to the present disclosure may be implemented in the form of a program product, which includes program code. When the program product runs on a terminal device, the program code is used to cause the terminal device to execute the steps according to various exemplary embodiments of the present disclosure described in the above "Exemplary Method" section of this specification.

[0046] The storage medium of the present disclosure may adopt any combination of one or more readable media. The readable media may be a readable signal medium or a readable storage medium. The readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples (a non-exhaustive list) of the readable storage medium include: an electrical connection having one or more wires, a portable disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.

[0047] The above description of the disclosed embodiments enables those skilled in the art to implement or use the present invention. Various modifications to these embodiments will be apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention will not be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A method for implementing secure communication of a MySQL database, characterized in that: The steps include: S1. Generate an SSL private key for the server in advance, use the SSL private key to generate a self-signed certificate, and encrypt the SSL private key and store it on the server; S2. Enable the SSL / TLS protocol when configuring the MySQL database on the server, and import the self-signed certificate and encrypted SSL private key; S3. The server responds to the client's request to connect to the MySQL database, decrypts the SSL private key, and uses the SSL private key and self-signed certificate to conduct encrypted communication with the client using the SSL / TLS protocol.

2. The method for realizing secure communication of MySQL database according to claim 1, characterized in that: The specific steps of step S1 are as follows: S11. Use OpenSSL tool on the server to generate SSL private key and SSL public key of preset length through RSA algorithm; S12. Use the SSL private key to sign the content containing the server identity information and create a certificate signing request; S13. Generate a certificate based on the certificate signing request, combining the SSL public key, server identity information and the preset certificate period, and sign the certificate using the SSL private key to obtain a self-signed certificate; S14. Encrypt the SSL private key to obtain the SSL private key ciphertext, and store the self-signed certificate and the SSL private key ciphertext on the server.

3. The method for realizing secure communication of MySQL database according to claim 2, characterized in that: The specific steps of step S2 are as follows: S21. When configuring the MySQL database on the server, obtain the storage location of the MySQL configuration file, the self-signed certificate, and the storage location of the SSL private key ciphertext; S22. Add the storage location of the self-signed certificate and the storage location of the SSL private key ciphertext to the MySQL configuration file; S23. Restart the MySQL database and the SSL / TLS protocol will take effect.

4. The method for realizing secure communication of MySQL database according to claim 3, characterized in that: The specific steps of step S3 are as follows: S31. When the client needs to connect to the MySQL database, a request for connecting using the SSL / TLS protocol is created; S32. The server responds to the client's request to connect to the MySQL database and sends the self-signed certificate to the client; S33. The server decrypts the SSL private key ciphertext to obtain the SSL private key; S34. The client verifies the validity of the self-signed certificate, generates a session key after verification, obtains the SSL public key from the self-signed certificate, encrypts the session key with the SSL public key to obtain the session key ciphertext, and sends the session key ciphertext to the server; S35. The server uses the SSL private key to decrypt the session key ciphertext and obtain the session key; S36. The client and server use the session key to perform encrypted communication using the SSL / TLS protocol.

5. The method for realizing secure communication of MySQL database according to claim 4, characterized in that: Step S3 also includes the following steps: SS1. The server generates a scheduled certificate update task based on the certificate expiration date; SS2. After the certificate update task is started, the SSL private key and self-signed certificate are regenerated on the server, the regenerated SSL private key is encrypted, and the regenerated SSL private key ciphertext and self-signed certificate are stored. Then the storage location of the self-signed certificate and the storage location of the SSL private key ciphertext in the MySQL configuration file are updated.

6. The method for realizing secure communication of MySQL database according to claim 4, characterized in that: The specific steps of step S14 are as follows: S141. The server generates an AES key and uses the AES key to encrypt the SSL private key to obtain the SSL private key ciphertext; S142. Store the signature certificate on the server and record the storage location; S143. The server creates an encrypted folder, stores the SSL private key ciphertext in the encrypted folder, and records the storage location; The specific steps of step S33 are as follows: S331. The server applies for administrator authorization to obtain access rights to the encrypted folder; S332. The server obtains the SSL private key ciphertext from the encrypted folder and decrypts it using the AES key to obtain the SSL private key.

7. The method for realizing secure communication of MySQL database according to claim 4, characterized in that: The specific steps of step S14 are as follows: S141. Generate a server key pair in advance, obtain the server public key and server private key, and store the server private key securely; S142. Use the server public key to encrypt the SSL private key to obtain the SSL private key ciphertext; S142. Store the signature certificate on the server and record the storage location; S143. The server creates an encrypted folder, stores the SSL private key ciphertext in the encrypted folder, and records the storage location; The specific steps of step S33 are as follows: S331. The server applies for the administrator's authorization to obtain access rights to the encrypted folder and obtains the server private key; S332. The server obtains the SSL private key ciphertext from the encrypted folder and decrypts it using the server private key to obtain the SSL private key.

8. A system for implementing secure communication of MySQL database, characterized in that: include: SSL private key encryption and self-signed certificate generation module, used to generate SSL private key for the server in advance, generate self-signed certificate using SSL private key, and encrypt the SSL private key and store it on the server; The secure communication configuration module is used to enable the SSL / TLS protocol when configuring the MySQL database on the server, and import the self-signed certificate and encrypted SSL private key; The secure communication module is used to decrypt the SSL private key when the server responds to the client's request to connect to the MySQL database, and to perform encrypted communication with the client using the SSL / TLS protocol through the SSL private key and self-signed certificate.

9. An electronic device, characterized in that: The invention comprises a memory, a processor and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of the method for implementing secure communication of a MySQL database as claimed in any one of claims 1 to 7 when executing the program.

10. A storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method for implementing secure communication of a MySQL database as claimed in any one of claims 1 to 7 are implemented.